Patentable/Patents/US-20260189892-A1
US-20260189892-A1

User Plane Function Event Exposure

PublishedJuly 2, 2026
Assigneenot available in USPTO data we have
Technical Abstract

Systems, methods, and machine-readable media for obtaining data from a cellular network core are described herein. A request from a network function residing outside of the cellular network core may be received by the cellular network core. The request may correspond to a request for data from the cellular network core. The request may be routed by a network exposure function (NEF) of the cellular network core to a user plane function (UPF) of the cellular network core. UPF data responsive to the request may be determined by the UPF. The UPF data may be transmitted from the UPF to the network function residing outside of the cellular network core.

Patent Claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

receiving, by a cellular network core, a request from a network function residing outside of the cellular network core, the request comprising an indication of an event type to be monitored; monitoring, by the cellular network core, network traffic or session information associated with user equipment for occurrence of an event corresponding to the indicated event type; consequent to detection of the event corresponding to the indicated event type, generating, by the cellular network core, an event exposure notification comprising information related to the detected event; and transmitting, by the cellular network core, the event exposure notification to the network function residing outside of the cellular network core. . A method for event exposure in a cellular network core, the method comprising:

2

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the request further comprises a filter specifying criteria for reporting the event exposure notification, the criteria comprising at least one of: a threshold for abnormal behavior, a maximum number of IP addresses, a time period, or an indication of whether reporting is to be performed one time, periodically, or in response to a detected event.

3

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event exposure notification comprises an identification of the user equipment, a type of the detected event, and data related to the network traffic associated with the detected event.

4

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event exposure notification is used to trigger a policy action within the cellular network core, the policy action comprising at least one of: increasing security for the user equipment, isolating traffic for the user equipment on a designated network slice, or modifying bandwidth allocation for the user equipment.

5

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event type corresponds to a deep packet inspection (DPI) event.

6

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event type corresponds to a quality of service (QoS) monitoring event.

7

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event type corresponds to a security-triggered event.

8

claim 1 . The method for event exposure in a cellular network core as recited in, wherein the event type corresponds to an application-specific event or a service-specific event.

9

claim 1 uplink bandwidth, downlink bandwidth, jitter, uplink packet delay, downlink packet delay, or roundtrip packet delay. . The method for event exposure in a cellular network core as recited in, wherein the event type corresponds to user traffic characteristics including at least one of:

10

receiving a request from a network function residing outside of the cellular network core, the request comprising an indication of an event type to be monitored; monitoring network traffic or session information associated with user equipment for occurrence of an event corresponding to the indicated event type; consequent to detection of the event corresponding to the indicated event type, generating an event exposure notification comprising information related to the detected event; and transmitting the event exposure notification to the network function residing outside of the cellular network core. a cellular network core configured to perform operations comprising: . A system comprising:

11

claim 10 . The system as recited in, wherein the request further comprises a filter specifying criteria for reporting the event exposure notification, the criteria comprising at least one of: a threshold for abnormal behavior, a maximum number of IP addresses, a time period, or an indication of whether reporting is to be performed one time, periodically, or in response to a detected event.

12

claim 10 . The system as recited in, wherein the event exposure notification comprises an identification of the user equipment, a type of the detected event, and data related to the network traffic associated with the detected event.

13

claim 10 . The system as recited in, wherein the event exposure notification is used to trigger a policy action within the cellular network core, the policy action comprising at least one of: increasing security for the user equipment, isolating traffic for the user equipment on a designated network slice, or modifying bandwidth allocation for the user equipment.

14

claim 10 . The system as recited in, wherein the event type corresponds to a deep packet inspection (DPI) event.

15

claim 10 . The system as recited in, wherein the event type corresponds to a quality of service (QoS) monitoring event.

16

claim 10 . The system as recited in, wherein the event type corresponds to a security-triggered event.

17

claim 10 . The system as recited in, wherein the event type corresponds to an application-specific event or a service-specific event.

18

claim 10 . The system as recited in, wherein the event type corresponds to user traffic characteristics including at least one of: uplink bandwidth, downlink bandwidth, jitter, uplink packet delay, downlink packet delay, or roundtrip packet delay.

19

receiving a request from a network function residing outside of a cellular network core, the request comprising an indication of an event type to be monitored; monitoring network traffic or session information associated with user equipment for occurrence of an event corresponding to the indicated event type; consequent to detection of the event corresponding to the indicated event type, generating an event exposure notification comprising information related to the detected event; and transmitting the event exposure notification to the network function residing outside of the cellular network core. . One or more non-transitory, machine-readable media having machine-readable instructions thereon which, when executed by one or more processing devices, cause a system to perform operations comprising:

20

claim 19 . The one or more non-transitory, machine-readable media as recited in, wherein the event exposure notification is used to trigger a policy action within the cellular network core, the policy action comprising at least one of: increasing security for the user equipment, isolating traffic for the user equipment on a designated network slice, or modifying bandwidth allocation for the user equipment.

Detailed Description

Complete technical specification and implementation details from the patent document.

This application is a continuation of U.S. Non-Provisional patent application Ser. No. 18/352,819, filed on Jul. 14, 2023, which claims priority to U.S. Provisional Patent Application Ser. No. 63/389,605, filed on Jul. 15, 2022, the disclosures of which are incorporated by reference in their entireties for all purposes.

Users use user equipment (UE) that communicates through a cellular network to access various networks, such as the Internet. Such access can include the user causing the UE to access a particular webpage. Such access can also include use of a service accessible via the Internet, such as a messaging application, gaming application, streaming application, business application, etc. Despite UE needing to generally have access to the Internet, care must be taken to ensure security on the cellular network is maintained. Further, particular applications or uses of the UE may require special handling in order to ensure an acceptable quality of experience (QoE) for the user and/or acceptable quality of service (QoS) parameters are met.

Certain embodiments of the present disclosure relate generally to cellular networks, and in particular to systems, methods, and computer-readable media for obtaining data from a cellular network core.

In some embodiments, methods for obtaining a cellular network address are presented. A method can include receive a request from a network function residing outside of a cellular network core of a cellular network, the request indicating an external Internet Protocol (IP) address associated with a user equipment (UE). The method can include routing, by a network exposure function of the cellular network core, the request to a user plane function (UPF) of the cellular network core. The method can include determining, by the UPF, the cellular network address for the UE that corresponds to the external IP address. The method can include routing, by the UPF, an indication of the determined cellular network address to the NEF. The method can include transmitting, by the NEF, the indication of the determined cellular network address to the network function residing outside of the cellular network core.

Embodiments of such methods can include one or more of the following features: The request can include an indication of DNN, an indication of S-NSSAI, or both. The indication of DNN, the indication of S-NSSAI, or both can be used to select the UPF from a plurality of UPFs of the cellular network core. The network function can reside outside of the cellular network. The method can include determining, by the NEF, whether the request from the network function is authorized, wherein routing the request to the UPF is performed after authorization is determined. The network function can be a traffic analysis gateway, wherein external network traffic for a plurality of UE that passes through the UPF is analyzed by the traffic analysis gateway. The method can include determining, by the traffic analysis gateway, that an event has occurred for the external IP address of the UE based on external network traffic. The request can be transmitted by the traffic analysis gateway in response to determining the event has occurred. The cellular network core is a 5G New Radio (NR) cellular network core.

In some embodiments, systems are presented. An embodiment of a system can include a cellular network core that comprises a user plane function (UPF) and a network exposure function (NEF). The core can be configured to receive a request from a network function residing outside of the cellular network core, the request indicating an external Internet Protocol (IP) address associated with a user equipment (UE). The core can be configured to route, by the NEF, the request to the UPF. The core can be configured to determine, by the UPF, a cellular network address for the UE that corresponds to the external IP address. The core can be configured to route, by the UPF, an indication of the determined cellular network address to the NEF. The core can be configured to transmit, by the NEF, the indication of the determined cellular network address to the network function residing outside of the cellular network core.

Embodiments of such a system can include one or more of the following features: The request can include an indication of DNN, an indication of S-NSSAI, or both. The indication of DNN, the indication of S-NSSAI, or both can be used to identify the UPF from a plurality of UPFs of the cellular network core. The core can be configured to determine, by the NEF, whether the request from the network function is authorized, wherein routing the request to the UPF is performed after authorization is determined. The system can include the network function, wherein the network function is a traffic analysis gateway, wherein external network traffic for a plurality of UE that passes through the UPF is analyzed by the traffic analysis gateway. The traffic analysis gateway can be configured to determine an event has occurred for the external IP address of the UE of the plurality of UE based on the external network traffic. The request can be transmitted by the traffic analysis gateway in response to determining the event has occurred. A policy of a plurality of stored policies can be applied to the cellular network address based at least in part on determining the event has occurred. The cellular network core is a 5G New Radio (NR) cellular network core. The NEF can be configured to receive a request for traffic characteristics of traffic corresponding to the UE. The NEF can be configured to transmit a data request to a session management function (SMF) to trigger the UPF to output data corresponding to the traffic characteristics of the traffic. The NEF can be configured to transmit the data corresponding to the traffic characteristics to the network function.

In another embodiment of a system, a network function may be present. The NF may reside outside of a cellular network core of a cellular network, that is authorized to communicate with a network exposure function (NEF) of the cellular network core, wherein the network function communicates with one or more application functions (AFs) residing outside of the cellular network. The system can include a radio access network (RAN), comprising a plurality of gNodeBs, that is in communication with the cellular network core. The cellular network core includes a user plane function (UPF) and the NEF. The core can be configured to receive a request from the network function residing outside of the cellular network core, the request indicating an external Internet Protocol (IP) address associated with a user equipment (UE). The core can be configured to route, by the NEF, the request to the UPF. The core can be configured to determine, by the UPF, a cellular network address for the UE that corresponds to the external IP address. The core can be configured to route, by the UPF, an indication of the determined cellular network address to the NEF. The core can be configured to transmit, by the NEF, the indication of the determined cellular network address to the network function residing outside of the cellular network core.

In one aspect, a method for obtaining data from a cellular network core is disclosed. The method may include one or a combination of the following. A request from a network function residing outside of the cellular network core may be received by the cellular network core. The request may correspond to a request for data from the cellular network core. The request may be routed by a NEF of the cellular network core to a UPF of the cellular network core. UPF data responsive to the request may be determined by the UPF. The UPF data may be transmitted from the UPF to the network function residing outside of the cellular network core.

In another aspect, a system disclosed herein may include a cellular network core. The cellular network core may include a UPF and a NEF. The cellular network core may be configured to perform one or a combination of the following operations. A request from a network function residing outside of the cellular network core may be received by the cellular network core. The request may correspond to a request for data from the cellular network core. The request may be routed by the NEF of the cellular network core to the UPF of the cellular network core. UPF data responsive to the request may be determined by the UPF. The UPF data may be transmitted from the UPF to the network function residing outside of the cellular network core.

In yet another aspect, one or more non-transitory, machine-readable media may be disclosed as having machine-readable instructions thereon which, when executed by one or more processing devices, cause the one or more processing devices to perform one or a combination of the following operations. A request from a network function residing outside of the cellular network core may be received by the cellular network core. The request may correspond to a request for data from the cellular network core. The request may be routed by a NEF of the cellular network core to a UPF of the cellular network core. UPF data responsive to the request may be determined by the UPF. The UPF data may be transmitted from the UPF to the network function residing outside of the cellular network core.

In various embodiments, the request for data may correspond to a request for an internal Internet Protocol (IP) address associated with user equipment residing outside of the cellular network core, and the UPF data may include the internal IP address. In various embodiments, the request from the network function may include an external IP address associated with the user equipment, and the internal IP address may be mapped to the external IP address. In various embodiments, the request for data may correspond to a request for mapping information that maps an external IP address associated with user equipment residing outside of the cellular network core to an internal IP address maintained by the cellular network core. In various embodiments, the request from the network function may be received by the NEF directly from the network function.

In various embodiments, the UPF data may be routed by the UPF to the NEF. The transmitting the UPF data from the UPF to the network function may include transmitting the UPF data from the NEF directly to the network function residing outside the cellular network core. In various embodiments, the request from the network function may include one or both of an indication of a DNN and an indication of S-NSSAI. In various embodiments, one or both of the DNN and the S-NSSAI may be used to select the UPF from a plurality of UPFs of the cellular network core. In various embodiments, the cellular network core is a 5G NR cellular network core.

Further areas of applicability of the present disclosure will become apparent from the detailed description provided hereinafter. It should be understood that the detailed description and specific examples, while indicating various embodiments, are intended for purposes of illustration only and are not intended to necessarily limit the scope of the disclosure.

A user plane function (UPF) resides within a core of a cellular network, such as the core of a 5G New Radio (NR) cellular network. The UPF serves as a gateway for network traffic between user equipment (UE) residing on the cellular network and an external network, which may be the Internet. A user of a UE connected with the cellular network may use the UE to access webpages or other services that are accessible via the Internet. Such services and applications can include: voice services and applications; video services and applications; gaming services and applications; communication services and applications; business services and applications; and emergency services and applications.

It may be beneficial to analyze communication traffic passing through the UPF and possibly perform some action, such as applying a policy to the traffic or the UE associated with the traffic, based upon the analysis. Not all traffic for a UE (uplink traffic and/or downlink traffic) is legitimate or secure. Therefore, situations may exist when particular traffic should be blocked, such as traffic that is suspicious, such as traffic that is possibly part of a distributed denial-of-service (DDOS) attack. As another example, particular applications and services may have varying needs in order to function sufficiently for a user of the UE to have a sufficient QoE. For example, a particular video chat application may require that particular latency requirements be met in order for a user to have an acceptable QoE.

As detailed herein, a service can be implemented that causes an NEF to query a UPF to obtain the cellular network address associated with a public IP address used for communication for the UE outside of the cellular network. Additionally, the UPF of a cellular network can be configured to output particular information relevant to UE, security and/or QoE for applications and services, for example, so that security and/or QoE for applications and services can be improved. The UPF can additionally or alternatively be configured to output QoS parameters for communication traffic for a particular UE through the UPF or communication traffic for a particular application or service being used by UE through the UPF.

Embodiments detailed herein can involve a traffic analysis gateway (TAG) that analyzes communication traffic passing through the UPF. Such analysis can involve deep packet inspection (DPI). Based upon an event being detected (e.g., suspicious or excessive traffic for a UE, a particular application or service being used by the UE), the TAG may obtain data from the UPF that indicates a mapping between a network address for the UE and the public address for the UE outside of the cellular network. The UPF may additionally or alternatively output QoS data to the TAG in some circumstances, such as for a particular application or service. The TAG can then determine whether a particular policy should be applied internally on the cellular network for the UE generally, application-specific traffic for the UE, or service-specific traffic for the UE. The internal policy applied within the cellular network can perform various purposes. For example, the UE may be reassigned to a cellular network slice with higher security; data associated with the application or service may receive higher than normal priority on the cellular network, or some other action can be performed.

1 FIG. Further detail regarding such embodiments is provided in relation to the figures. The implementations detailed herein can be implemented on a hardware-based cellular network. A hardware-based cellular network can use specialized or general-purpose computing hardware maintained directly by the cellular network provider to provide cellular services. Alternatively, implementations detailed herein can be performed on a hybrid-cloud cellular network, such as detailed in relation to.

The core of a 5G New Radio (NR) cellular network can employ a service-based architecture (SBA) using a service-based interface. At the core of most modern networks and services is typically a cloud-and virtualization-based platform. This is also the case for 5G networks. A cloud-and virtualized platform can be programmable and can allow many different functions to be built, configured, connected, and deployed at the scale that is needed at the given time. The 3rd Generation Partnership Project (3GPP) defines an SBA whereby the control plane functionality and common data repositories of a 5G NR network are delivered by way of a set of interconnected network functions (NFs), each with authorization to access each other's services. SBAs can provide a modular framework from which common applications can be deployed using components of varying sources and suppliers. The service-based interface can function based on API calls.

1 FIG. 1 FIG. 100 100 110 110 1 110 2 110 3 115 120 125 125 127 127 129 129 139 138 illustrates a block diagram of a hybrid cellular network system (“system 100”). Such a hybrid cellular network system is partially implemented using specialized hardware and partially implemented using virtualized cellular network components on a cloud-computing platform, such as Amazon Web Services (AWS). Systemcan include a 5G New Radio (NR) cellular network; as noted, other types of cellular networks, such as 6G, 7G, etc., may also be possible. Systemcan include: UE(UE-, UE-, UE-); structure; cellular network; radio units(“RUs”); distributed units(“DUs”); centralized unit(“CU”); 5G core; and orchestrator.represents a component-level view. In a virtualized open radio access network (O-RAN), because components can be implemented as specialized software executed on general-purpose hardware, except for components that need to receive and transmit RF, the functionality of the various components can be executed by general-purpose servers. For at least some components, the hardware may be maintained by a separate cloud-service computing platform provider. Therefore, the cellular network operator may operate some hardware, such as base stations that include RUs and local computing resources on which DUs are executed, such components may be connected with a cloud-computing platform on which other cellular network functions (NFs), such as the cellular network core and higher-level RAN components, such as CUs, are executed.

110 110 120 121 1 115 1 125 1 127 1 115 1 115 1 121 2 115 2 125 2 127 2 UEcan represent various types of end-user devices, such as cellular phones, smartphones, cellular modems, cellular-enabled computerized devices, sensor devices, robotic equipment, IoT devices, gaming devices, access points (APs), or any computerized device capable of communicating via a cellular network. More generally, UE can represent any type of device that has an incorporated 5G interface, such as a 5G modem. Examples can include sensor devices, Internet of Things (IoT) devices, manufacturing robots, unmanned aerial (or land-based) vehicles, network-connected vehicles, etc. Depending on the location of individual UEs, UEmay use RF to communicate with various BSs of cellular network. As illustrated, two BSs are illustrated; BS-can include: structure-, RU-, and DU-. Structure-may be any structure to which one or more antennas (not illustrated) of the BS are mounted. Structure-may be a dedicated cellular tower, a building, a water tower, or any other man-made or natural structure to which one or more antennas can reasonably be mounted to provide cellular coverage to a geographic area. Similarly, BS-can include: structure-, RU-, and DU-.

100 139 121 1 125 110 125 120 125 120 121 125 1 127 1 Real-world implementations of systemcan include many (e.g., thousands) of BSs and many CUs and 5G core. BS-can include one or more antennas that allow RUsto communicate wirelessly with UEs. RUscan represent an edge of cellular networkwhere data is transitioned to RF for wireless communication. The radio access technology (RAT) used by RUmay be 5G NR, or some other RAT. The remainder of cellular networkmay be based on an exclusive 5G architecture, a hybrid 4G/5G architecture, or some other cellular network architecture that supports cellular network slices. BSmay include an RU (e.g., RU-) and a DU (e.g., DU-).

125 1 127 1 71 127 1 129 120 127 129 139 120 120 120 127 1 129 139 One or more RUs, such as RU-, may communicate with DU-. As an example, at a possible cell site, three RUs may be present, each connected with the same DU. Different RUs may be present for different portions of the spectrum. For instance, a first RU may operate on the spectrum in the citizens broadcast radio service (CBRS) band while a second RU may operate on a separate portion of the spectrum, such as, for example, band. In some embodiments, an RU can also operate on three bands. One or more DUs, such as DU-, may communicate with CU. Collectively, an RU, DU, and CU create a gNodeB, which serves as the radio access network (RAN) of cellular network. DUsand CUcan communicate with 5G core. The specific architecture of cellular networkcan vary by embodiment. Edge cloud server systems (not illustrated) outside of cellular networkmay communicate, either directly, via the Internet, or via some other network, with components of cellular network. For example, DU-may be able to communicate with an edge cloud server system without routing data through CUor 5G core. Other DUs may or may not have this capability.

1 FIG. 120 120 120 125 110 120 127 129 139 139 129 Whileillustrates various components of cellular network, other embodiments of cellular networkcan vary the arrangement, communication paths, and specific components of cellular network. While RUmay include specialized radio access componentry to enable wireless communication with UE, other components of cellular networkmay be implemented using either specialized hardware, specialized firmware, and/or specialized software executed on a general-purpose server system. In a virtualized arrangement, specialized software on general-purpose hardware may be used to perform the functions of components such as DU, CU, and 5G core. Functionality of such components can be co-located or located at disparate physical server systems. For example, certain components of 5G coremay be co-located with components of CU.

129 139 138 128 139 100 128 129 139 138 128 128 In a possible virtualized implementation, CU, 5G core, and/or orchestratorcan be implemented virtually as software being executed by general-purpose computing equipment on public cloud-computing platform, as detailed herein. Therefore, depending on needs, the functionality of a CU, and/or 5G core may be implemented locally to each other and/or specific functions of any given component can be performed by physically separated server systems (e.g., at different server farms). For example, some functions of a CU may be located at a same server facility as where 5G coreis executed, while other functions are executed at a separate server system or on a separate cloud computing system. In the illustrated embodiment of system, cloud-computing platformcan execute CU, 5G core, and orchestrator. The cloud-computing platformcan be a third-party cloud-based computing platform or a cloud-based computing platform operated by the same entity that operates the RAN. Cloud-based computing platformmay have the ability to devote additional hardware resources to cloud-based cellular network components or implement additional instances of such components when requested.

120 Kubernetes, Docker®, or some other container orchestration platform, can be used to create and destroy the logical CU or 5G core units and subunits as needed for the cellular networkto function properly. Kubernetes allows for container deployment, scaling, and management. As an example, if cellular traffic increases substantially in a region, an additional logical CU or components of a CU may be deployed in a data center near where the traffic is occurring without any new hardware being deployed. (Rather, processing and storage capabilities of the data center would be devoted to the needed functions.) When the need for the logical CU or subcomponents of the CU no longer exists, Kubernetes can allow for removal of the logical CU. Kubernetes can also be used to control the flow of data (e.g., messages) and inject a flow of data to various components. This arrangement can allow for the modification of nominal behavior of various layers.

138 138 138 120 The deployment, scaling, and management of such virtualized components can be managed by orchestrator. Orchestratorcan represent various software processes executed by underlying computer hardware. Orchestratorcan monitor cellular networkand determine the amount and location at which cellular network functions should be deployed to meet or attempt to meet service level agreements (SLAs) across slices of the cellular network.

138 120 138 120 Orchestratorcan allow for the instantiation of new cloud-based components of cellular network. As an example, to instantiate a new CU for test, orchestratorcan perform a pipeline of calling the CU code from a software repository incorporated as part of, or separate from cellular network, pulling corresponding configuration files (e.g. helm charts), creating Kubernetes nodes/pods, loading CU containers, configuring the CU, and activating other support functions (e.g. Prometheus, instances/connections to test tools).

120 As previously noted, a cellular network slice functions as a virtual network operating on an underlying physical cellular network. Operating on cellular networkis some number of cellular network slices, such as hundreds or thousands of network slices. Communication bandwidth and computing resources of the underlying physical network can be reserved for individual network slices, thus allowing the individual network slices to reliably meet defined SLA requirements. By controlling the location and amount of computing and communication resources allocated to a network slice, the QoS and QoE for UE can be varied on different slices. A network slice can be configured to provide sufficient resources for a particular application to be properly executed and delivered (e.g., gaming services, video services, voice services, location services, sensor reporting services, data services, etc.). However, resources are not infinite, so allocation of an excess of resources to a particular UE group and/or application may be desired to be avoided. Further, a cost may be attached to cellular slices: the greater the amount of resources dedicated, the greater the cost to the user; thus, optimization between performance and cost is desirable.

Particular parameters that can be set for a cellular network slice can include: uplink bandwidth per UE; downlink bandwidth per UE; aggregate uplink bandwidth for a client; aggregate downlink bandwidth for the client; maximum latency; access to particular services; and maximum permissible jitter.

125 1 127 1 125 2 127 2 Particular network slices may only be reserved in particular geographic regions. For instance, a first set of network slices may be present at RU-and DU-, and a second set of network slices, which may only partially overlap or may be wholly different from the first set, may be reserved at RU-and DU-.

Further, particular cellular network slices may include multiple defined slice layers. Each layer within a network slice may be used to define parameters and other network configurations for particular types of data. For instance, high-priority data sent by a UE may be mapped to a layer having relatively higher QoS parameters and network configurations than lower-priority data sent by the UE that is mapped to a second layer having relatively less stringent QoS parameters and different network configurations.

127 129 138 139 Components such as DUs, CU, orchestrator, and 5G coremay include various software components that are required to communicate with each other, handle large volumes of data traffic, and are able to properly respond to changes in the network. In order to ensure not only the functionality and interoperability of such components, but also the ability to respond to changing network conditions and the ability to meet or perform above vendor specifications, significant testing must be performed.

2 FIG.A 1 FIG. 200 200 210 210 139 210 212 212 214 214 216 216 218 218 220 212 214 216 218 218 210 218 220 218 illustrates an embodiment of a cellular network systemA (“systemA”) that includes a cellular network core that exposes data from the user plane function (UPF) to a network function residing outside of cellular network coreand, possibly, outside of the cellular network. A network function can refer to a computerized function that interacts with data stored by and/or created by components of the cellular network. Corecan represent an embodiment of 5G coreof. Corecan include: Unified Data Management(“UDM”); Session Management Function(“SMF”); Policy Control Function(“PCF”); Network Exposure Function(“NEF”); and UPF. UDMis a network function that manages access authorization, user registration, and roaming access. SMFmanages interactions on the data plane, creation and removal of protocol data unit sessions and managing session context with the UPF. PCFgoverns control plane functions and the UPF via defined policy rules. NEFfacilitates exposure of network services and capabilities to trusted components outside of the cellular network core. NEFcan act as a consolidated application programming interface (API) for components of core. Via NEF, permissions and access to data from core components, including UPF, can be controlled. NEFcan provide for application functions to securely provide information to a 3GPP network. In this case, the NEF may authenticate, authorize, and/or assist in throttling application functions.

220 240 205 205 121 120 220 210 205 240 220 1 FIG. UPFis responsible for packet routing and forwarding between external networks from the cellular network (e.g., Internet) and UE communicating with RANof the cellular network. RANcan represent BSsof cellular networkof. UPFfunctions as a gateway in that cellular network addressed traffic inside of coreand RANis translated to have an external IP address appropriate for communication via Internet. From the perspective of a UE, all inbound and outbound Internet communications flows through UPF.

200 230 210 230 230 220 210 210 231 230 231 230 231 2 FIG.B 2 FIG.A 2 FIG.A In systemA, network function (NF)resides outside of core. Network functionmay be any form of network function that interacts with IP addresses used for data communication outside of the cellular network. An example of such a network function is provided in relation to. In, network functionmay need the private IP address (also referred to as a cellular network address) used within the cellular network that is mapped to the public IP address used outside of the cellular network. As an example, when a UE requests a website, UPFmodifies the request to include a different, external (also referred to as public) IP address that is used for transmitting the request outside of the cellular network and core. As such, the private IP address used within the cellular network and coreremains obscured to the website and any other intercepting party outside of the cellular network. As shown in, application function (AF)may be present. While NFcan be operated by the cellular network operator, AFmay be operated by a separate party. NFmay determine whether AFis permitted to request the internal cellular network address.

218 230 230 218 218 218 230 218 220 218 218 230 220 218 230 Via NEF, network functioncan request the private IP address of a UE. Network functionmay transmit a request to NEFthat includes: 1) the public IP address associated with the desired private IP address; and, possibly, 2) a port. This request may be transmitted to NEF. NEFmay then determine if network functionis authorized to perform such a request. If authorized, NEFmay then transmit the public IP address (and port) to UPF. In response, the UPF may look up the associated private IP address and provide the private IP address to NEF. NEFmay then provide a response to network functionthat indicates the private IP address of the UE. In some embodiments, UPFcan also provide an indication of IP domain to NEF, which can then be output to network function.

230 218 230 In some embodiments, network functionmay have access to additional data that can be included in the request. The additional data can include: an IP domain; an indication of the data network name (DNN); and/or the S-NSSAI (Single Network Slice Selection Assistance Information). A cellular network can include multiple instances of UPFs. At a given time, a particular UPF instance may handle the communications for a given UE. This additional data can be used by NEFto route the request to the correct UPF instance that is handling UPF functionality for the UE, such as if multiple UPF instances can allocate IP addresses within the same external IP range. As an example, NFmay have access to data from a stored service level agreement (SLA) that defines a relationship between an application function making a request and a corresponding DNN and/or S-NSSAI. Therefore, based on a look-up, the DNN and/or S-NSSAI can be determined based on the AF from which the request originated.

2 FIG.B 1 FIG. 1 FIG. 200 200 220 210 139 220 240 205 205 121 120 220 210 205 240 220 220 illustrates an embodiment of a cellular network systemB (“systemB”) that includes a cellular network core that exposes data from UPF. Corecan represent an embodiment of 5G coreof. UPFis responsible for packet routing and forwarding between external networks from the cellular network (e.g., Internet) and UE communicating with RANof the cellular network. RANcan represent BSsof cellular networkof. UPFfunctions as a gateway in that cellular network addressed traffic inside of coreand RANis translated to have an external IP address appropriate for communication via Internet. From the perspective of a UE, all inbound and outbound Internet communications flows through UPF. Therefore, by monitoring data passing through UPF, the Internet traffic for all UE using the cellular network for Internet access can be monitored.

200 250 250 220 240 250 220 240 220 250 236 232 220 250 250 233 218 218 218 220 235 250 218 235 235 235 220 250 220 218 220 250 218 220 3 FIG. In systemB, TAG, which is an example of an application function and is detailed in relation to, is present. TAGmonitors inbound and/or outbound communication traffic between UPFand Internet. TAGmay be positioned between UPFand Internetsuch that Internet traffic inbound and outbound from UPFpasses through TAG. Internet trafficand internet trafficcan have external IP addresses attached. Without information from UPF, TAGmay be unable to determine which UE on the cellular network or cellular network address that is associated with the external IP address. Inbound and/or outbound communication traffic may be analyzed by TAG. Based on an event being detected in traffic associated with a particular external IP address, traffic analysis gateway may transmit a requestfor access to UPF data to NEF. This request can indicate the external IP address for which the event was detected. This request can be in the form of an API call. If NEFapproves the request, NEFtransmits a message, which can include the external IP address for which the event was detected, to UPFthat causes UPF datato be output to TAG, either directly or via NEF. UPF datacan be an indication of the corresponding cellular network address (private IP address). Additionally or alternatively, UPF datacan include various pieces of information, such as: 1) a mapping of the external IP address to a cellular network address for the UE; and 2) one-time, occasional, or periodic direct reporting of QoS monitoring events (DRQOS). UPF datacan be transmitted by UPFto TAGby virtue of permission being granted to UPFvia NEF; alternatively, data may be transmitted by UPFto TAGvia NEF. Data from UPFcan be transmitted in the form of an API call.

250 250 250 210 234 234 Depending on the type of event detected, TAGcan take various actions. If a security event has been detected, such as inbound or outbound data being associated with a DDOS attack, virus, or some other security event, TAGmay block inbound and/or outbound traffic associated with the UE. TAGcan send corepolicy request. Policy requestmay request that a policy be applied to a particular cellular network address (and, therefore, for a particular UE). The policy request may request that a policy be applied that: included increases security; isolates the UE's traffic on a designated slice; causes one or more NFs to not be available; causes one or more additional NFs to be used; decreases the uplink and/or downlink bandwidth provided to the UE; and/or some other action.

250 If the event detected is the use of some particular service or application, TAGmay use the DRQOS to determine if a policy should be applied that alters the QoS provided to the UE on the cellular network. For example, the particular services or applications that may be monitored for can include various over-the-top (OTT) communication services, such as Skype, WhatsApp, media streaming services (e.g., Spotify, Tidal, Netflix, Disney+, AppleTV, Prime Video, etc.). Depending on the DRQOS data, if one or more thresholds are triggered (e.g., uplink bandwidth, downlink bandwidth, jitter, uplink packet delay, downlink packet delay, and/or roundtrip packet delay between the UPF and UE on the cellular network exceeding defined threshold values), a policy may be applied to the cellular network address (and, thus, the UE) for which the event was detected that helps improve performance for the application or service. Such thresholds may be particular to the application or service and may have been defined by the application provider, service provider, or cellular network operator. The policy may generally improve performance for all traffic for the UE or only traffic associated with the particular service or application. In some arrangements, such a policy may instead be used to decrease performance for a particular service or application, such as a service or application that the cellular network operator wants to discourage users from using (e.g., downloads from sources known to host pirated material) or is perhaps associated with security vulnerabilities (e.g., downloads from sources known to host viruses).

250 250 250 218 250 220 220 250 250 210 250 As an example, TAGmay analyze internet traffic associated with a particular external IP address. Based on the analysis, TAGmay determine that the traffic is associated with a particular gaming service (e.g., based on the IP address to which data is being sent by the UE, such as a target IP address of an application server). TAGmay send a request indicating the external IP address to NEFalong with an indication that TAGis requesting DRQOS data, which may in turn approve and send the request to UPF. UPFmay then output the DRQOS data to TAGalong with, possibly, a mapping between the external IP address and a cellular network address. Depending on the DRQOS data, TAGmay or may not request coreto apply a particular policy to the cellular network address. As another example, TAGcan determine whether network address translation (NAT) may be needed.

250 250 250 218 250 218 220 220 250 234 As another example, TAGmay analyze outbound internet traffic associated with a particular external IP address. Based on the analysis, TAGmay determine that the traffic is related to a security event. TAGmay send a request indicating the external IP address to NEFalong with an indication that TAGis requesting an IP mapping. NEFmay in turn approve and send the request to UPF. UPFmay then output the mapping between the external IP address and a cellular network address. TAGmay then send policy requestrequesting that a particular policy be applied to the cellular network address mapped to the external IP address for which the security event was detected.

234 In some embodiments, based on policy request, a message may be transmitted to and output by the UE that acts as a report to the user. For example, if a UE or cellular network address of the UE is determined to be involved in a DDOS attack, the UE may be caused to present a message that indicates as such and recommend steps for the user of the UE to take. If a policy is applied to improve performance for a particular application, a message may be output to the UE that indicates that a policy has been applied to improve the QoE for the particular application.

3 FIG. 1 FIG. 300 250 250 310 320 330 335 340 350 250 250 250 139 illustrates an embodimentof TAGwith various data traffic. TAGcan include: traffic analyzer; NEF interface; QoS monitor; Application/Service QoS Guide; policy engine; and policy datastore. Components of TAGmay include one or more special-purpose or general-purpose processors. Such special-purpose processors may include processors that are specifically designed to perform the functions of the components detailed herein. Such special-purpose processors may be ASICs or FPGAs which are general-purpose components that are physically and electrically configured to perform the functions detailed herein. Such general-purpose processors may execute special-purpose software that is stored using one or more non-transitory processor-readable mediums, such as random-access memory (RAM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). Further, the functions of the components of TAGcan be implemented using a cloud-computing platform, which is operated by a separate cloud-service provider that executes code and provides storage for clients. For example, as detailed in relation to, TAGcan be implemented on the cloud-computing platform that hosts 5G core.

310 301 302 312 310 Traffic analyzermay analyze inbound and/or outbound traffic between a UPF and an external network, such as the Internet. Therefore, trafficmay be exchanged with a UPF and trafficmay be exchanged with the external network. In some embodiments, DPI may be performed by deep packet inspectorto determine a particular service or application corresponding to traffic. Such DPI may also be beneficial for analyzing security risks. Some forms of analysis that may be performed by traffic analyzercan include: monitoring inbound data volumes for an external IP address; monitoring outbound data volumes for the external IP address; monitoring addresses to which data is being transmitted to and/or received from.

320 303 304 330 NEF interfacecan serve to send messagesor requests for data to the NEF of the cellular network core. These messages can include data such as: 1) the type of data requested (e.g., DRQOS data, IP mapping data); 2) the external IP address for which the data is requested; and possibly 3) a time duration for which the data should be provided. In response to the NEF approving the request, the UPF may be triggered to output QoS datato QoS monitor.

330 304 335 335 330 340 QoS monitormay analyze QoS datareceived from the UPF and compare such data with corresponding thresholds in App/Service QoS Guide. App/Service QoS Guidemay be organized such that particular thresholds (or other forms of performance parameters) are mapped to particular services or applications. The particular threshold relevant to the one or more applications or services for which the QoS data is received from the UPF may be compared with the QoS data by QoS monitor. If the comparison indicates that a policy should be applied to improve (or decrease) performance, policy enginemay be triggered to do so.

340 306 306 Policy enginemay cause the cellular network core to apply one or more policies to a particular internal cellular network address (which would apply to a particular UE). A policy request messagemay indicate: 1) the cellular network address to which the policy should be applied; 2) an identifier of the policy or parameters of the policy to apply; and possibly 3) an amount of time for which the policy should be applied. Such policy request messagesmay be transmitted to the cellular network core.

340 305 310 306 Policy enginemay receive or otherwise be able to access IP address mappings received from the UPF. IP address mappingcan indicate the cellular network address mapped to a particular external IP address. While traffic analyzermay detect events associated with external IP addresses, policies may be applied by the cellular network core to cellular network addresses; therefore, when a policy request messageis sent to the cellular network core, the correct cellular network address may need to be indicated.

340 330 310 350 306 340 350 310 350 340 330 Policy enginebased on a trigger from QoS monitorand/or an indication of the type of event detected for the external network address from traffic analyzermay cause a policy, as indicated in policy datastore, to be applied by sending policy request message. In some situations, such as for a security event, QoS data may not be relevant; therefore, policy enginemay only need the correct cellular network address for which a policy should be applied. Policies in policy datastoremay be indicated by an identifier (or parameters) and the circumstances under which the policy should be applied. For example, a policy may be applied based on a particular type of event (e.g., a security event) being detected by traffic analyzer. As another example, a particular policy from policy datastoremay be applied by policy enginewhen triggered by QoS monitorfor a particular service or application. Such a policy may be defined to remedy QoE issues for the particular service or application based on QoS parameters not being met.

1 3 FIGS.- 4 FIG.A 2 FIG.A 400 400 Various methods may be performed using the systems and arrangements of.illustrates an embodiment of a methodA for exposing an internal cellular network address from the UPF to a network function residing outside the cellular network core (and, possibly, cellular network). MethodA may be performed using a network function, such as detailed in relation to.

401 402 403 At block, a request may be transmitted by a network function residing outside of the cellular network core (or outside of the cellular network) to the NEF of the cellular network that indicates that a cellular network address (e.g., private IP address) from the UPF is requested. This request can indicate the external IP address for which the corresponding private IP address from the UPF is requested. The NEF can approve or deny this request at block, such as based on the external IP address and whether the network function is authorized to make such a request. At block, if approved, the NEF can transmit the request to the UPF. In some embodiments, additional optional data, such as the IP domain, DNN, and/or S-NSSAI may be used to determine the correct instance of the UPF of the cellular network to which the request should be routed.

404 At block, in response to the request, the UPF may provide an indication of the cellular network address corresponding to the external IP address of the UE.

4 FIG.B 2 3 FIGS.B and 400 400 illustrates an embodiment of a methodB for exposing and using data from the UPF. MethodB may be performed using a TAG, such as detailed in relation to, along with a UPF that is configured to output IP mapping data and, possibly, QoS data.

405 410 410 At block, external communications between a UPF and a network (inbound for the UPF and/or outbound from the UPF), such as the Internet, are received. The external communications are analyzed, possibly using DPI, at block. Blockcan include one or more events being detected. An event can include: a security event; a particular type of security event; a particular service being used; and/or a particular application being used.

415 410 420 At block, in response to the event of block, a request may be transmitted by the TAG to the NEF of the cellular network indicating that data from the UPF is requested. This request can indicate the external IP address for which data from the UPF is requested and may indicate whether QoS data is requested. The NEF can approve or deny this request. If approved, the UPF may be triggered by the NEF to fulfill the request at block.

425 415 430 At block, in response to the UPF being triggered, the UPF may provide a mapping between the external IP address, which may have been indicated in the triggering request to the UPF from the NEF, and a cellular network address to the TAG that transmitted the request at block. Additionally, if requested, at block, DRQOS data for the cellular network address (which corresponds to a particular UE) may be output to the TAG. This DRQOS data may only correspond to a particular service or application, or alternatively may apply to all traffic passing through the UPF for the cellular network address.

435 410 430 At block, the TAG may trigger one or more policies to be applied to the cellular network address based on the event detected at blockand/or a comparison between the DRQOS data received at blockand QoS parameter thresholds particular to the service or application being used by the UE. The policy may be set by the TAG sending a policy message to the cellular network core that either indicates the particular parameters of the policy to be applied or includes an identification of the policy to be applied (and the actual policy may be retrieved from some other source by the cellular network core). Alternatively, the policy may be applied by some component in communication with the cellular network external to the core.

435 Following block, the UE may continue to access the service or application while the UE's access to the cellular network is controlled in accordance with the applied policy. In some situations, such as for a security event, the policy may include a complete quarantine or block of the UE from accessing the external network. In some embodiments, a notification may be output by the UE indicating the policy applied and/or event that occurred.

5 FIG. 500 500 Various methods may be performed according to various embodiments to expose new data from the UPF. For example,illustrates an operation flow diagram corresponding to an embodiment of a methodfor exposing and using UPF data via the SMF. The methodmay use predetermined event IDs corresponding to NEF events and may be advantageous for ease of deployment in view of current systems and standards. Likewise, utilizing the SMF for NEF event exposure and UPF data may be advantageous for ease of deployment in view of current systems and standards.

505 250 218 250 250 As indicated by, the TAGmay communicate a request for access to UPF data to the NEF. For example, the request may correspond to an NEF event exposure request and may include one or more indicators. The one or more indicators may correspond to parameters specifying the event exposure request (e.g., IP address mapping information requests, DPI requests, target application/UE IP addresses, event detection criteria, and/or the like). The request may include one or more event IDs, specifying one or more events for which the TAGrequests access to corresponding UPF data. For example, the event may include protocol data unit (DPU) session status. This event may correspond to detecting when a PDU session is established or released for any UE, a specific UE, a group of UEs, or UEs that belong to a particular network slice. The TAGrequest may specify the one or more external IP addresses corresponding to the one or more UEs and/or may specify parameters of the network slice of interest.

250 250 250 250 250 250 The TAGmay provide additional parameters, such as an indication of a need for mapping information between the one or more external IP addresses and one or more cellular network addresses of the one or more PDU sessions. In various embodiments, the TAGmay request one or more UE private IP addresses (e.g., internal/private cellular network addresses) with or without mapping information. The TAGmay specify target applications, services, addresses, and/or the like for DPI operations. The TAGmay further provide specifications for a DPI case for release or deactivation that may correspond to the application IP address used by the PDU session, which applications/AFs the particular UEs accessed in the PDU session (e.g., particular websites accessed, applications used, etc.), a threshold, a maximum number of IP addresses, and/or the like. As disclosed above, the TAGrequest may include data such as: 1) the type of data requested (e.g., DRQOS data, UE private IP addresses, IP address mapping data mapping between external/public IP addresses and UE private IP addresses such as internal/private cellular network addresses); 2) the external IP address for which the data is requested; and possibly 3) a time duration for which the data should be provided. The NFs that detect the PDU session status event may correspond to the SMF and/or the UPF, and, as disclosed herein, the TAGis an example of an application function.

Moreover, various embodiments may include various types of events which can be specified and used for obtaining UPF data. One event may correspond to user traffic characteristics and/or uplink data characteristics. The detection criteria for this event may specify detecting suspicious and/or excessive traffic (e.g., for a UE, a particular application or service being used by the UE), when one or more thresholds are triggered (e.g., inbound data volumes, outbound data volumes, uplink bandwidth, downlink bandwidth, jitter, uplink packet delay, downlink packet delay, and/or roundtrip packet delay between the UPF and UE), downloads from particular sources, particular destinations for data transfers, particular UE operational patterns, compromised service patterns, particularized attack patterns, particular types of access operations and/or other operations, and/or the like. Such detection criteria may be specified in the parameters of the event exposure request. The NFs that detect the event may correspond to the UPF and/or the network data analytics function (NWDAF).

250 Another event may correspond to NAT mapping information or, in some embodiments, a request for one or more UE private IP addresses without the mapping information. The detection criteria for this event may specify detecting, for a UE or a group of UEs, mapping information between cellular network addresses and external IP addresses, between UE private IP addresses and UE public IP addresses (e.g., IP addresses and ports), which may include Subscription Permanent Identifiers (SUPIs). Another event may correspond to UE reachability. The detection criteria for UE reachability may include detecting when the UE transitions to CM-connected state or when the UE will become reachable for paging, e.g., via a periodic registration update timer. It may indicate when the UE becomes reachable for sending downlink data to the UE. The TAGmay specify a maximum latency for the detection criteria. The NFs that detect the event may correspond to the access and mobility management function (AMF) and/or the UDM.

Another event may correspond to location reporting. The detection criteria for location reporting may include detecting based on event reporting information parameters (e.g., one-time reporting, maximum number of reports, maximum duration of reporting, periodicity, etc.). The location reporting may report either the current location or the last known location of a UE. The NFs that detect the event may correspond to the AMF and/or the gateway mobile location center (GMLC). Another event may correspond to roaming status. The detection criteria for this event may specify detecting based on the UE's current roaming status (the serving public land mobile network (PLMN) and/or whether the UE is in its home public land mobile network (HPLMN)) and notification is sent when that status changes. If the UE is registered via both 3GPP and N3GPP Access Type, then both instances of roaming status may be included. The NFs that detect the event may correspond to the UDM.

250 Another event may correspond to a communication failure. Detection criteria for this event may specify detecting when RAN or NAS level failure is detected based on connection release and it identifies a RAN/NAS release code. Another event may correspond to availability after downlink data notification failure. The detection criteria for this event may specify detecting when the UE becomes reachable again after downlink data delivery failure. When requesting availability after downlink data notification failure monitoring, the TAGmay additionally request an idle status indication to be included in the UE reachability event reporting. The NFs that detect the events may correspond to the AMF.

Another event may correspond to core network (CN) type change. The detection criteria for this event may specify detecting when the UE moves between evolved packet core (EPC) and 5GC. It may indicate the current CN type for a UE or a group of UEs when detecting that the UE switches between being served by a Mobility Management Entity (MME) and an Access and Mobility Management Function (AMF) or when accepting the event subscription. The NFs that detect the event may correspond to the SMF. Another event may correspond to downlink data delivery status. The detection criteria for this event may specify detecting the downlink data delivery status in the core network. Events may be reported at the first occurrence of packets being buffered, transmitted or discarded, including: downlink data in extended buffering, first data packet buffered event, estimated buffering time, first downlink data transmitted event, and first downlink data discarded event. The NFs that detect the event may correspond to the SMF.

Another event may correspond to UE reachability for SMS delivery. The detection criteria for this event may specify detecting when a Short Message Service Function (SMSF) is registered for a UE and the UE is reachable as determined by the AMF and the UDM. This may enable the UE to receive an SMS. The NFs that detect the event may correspond to the UDM. Another event may correspond to number of registered UEs or established PDU Sessions. The detection criteria for this event may specify detecting the current number of registered UEs or established PDU Sessions for a network slice that is subject to Network Slice Admission Control (NSAC). For one-time reporting with an immediate reporting flag set, the NSAC function may report the number of registered UEs or established PDU sessions immediately. The NFs that detect the event may correspond to the network slice access control function (NSACF). Another event may correspond to an area of interest. The detection criteria for this event may specify detecting change of the UE presence in an area of interest. The NFs that detect the event may correspond to the AMF and/or the GMLC.

510 218 212 218 As indicated by, the NEFmay communicate a message corresponding to the request to the UDM. Such a message may be in response to the NEFapproving the request. In some embodiments, the message may be identical to the request. The message may include the event ID and the parameters of the request, which may include specifications of the detection criteria. As one example out of many, the event ID may identify PDU sessions status, and the parameters may identify the indicators for the event.

515 212 214 212 214 520 214 220 220 As indicated by, the UDMmay communicate a corresponding message to the SMF. The UDMmay manage access authorization and coordinate event exposure corresponding to the event ID and the parameters of the request with the SMF. As indicated by, the SMFmay communicate with the UPFto provision the event parameters and obtain requested UPF data. For example, the UPFmay retrieve and provide IP mapping information, one or more UE private IP addresses with or without mapping information, and/or other UPF data corresponding to the one or more UE public IP addresses provided with the event disclosure request.

525 As another example, the parameters may include specifying abnormal IP address detection. As indicated by, DPI may be performed for select IP addresses. In various cases, the DPI may be performed based on a filter for unusual IP addresses (e.g., comparison to a user-specified or machine-learned/developed list of approved/verified/known addresses, hosts, and/or network IDs and/or of prohibited/flagged/suspicious addresses, hosts, and/or network IDs) or based on all IP addresses corresponding to the parameters and/or IP addresses related to unusual/abnormal IP addresses.

530 214 535 214 220 214 220 As indicated by, the SMFmay decide when and whether the PDU session should be released or deactivated. Such a decision be based on the event parameters provided with the event exposure request, which may be in accordance with the event parameters, timing parameters, etc. Thus, in some cases, the decision be based upon event detection satisfying the detection criteria according to the specified event detection requested. As indicated by, the SMFmay communicate with the UPFto coordinate a release. In some cases, the SMFmay instruct the UPFto release.

540 220 214 545 214 218 550 218 250 218 218 250 As indicated by, the UPFmay respond to the SMFwith the requested UPF data. For example, the response may include one or more UE private IP addresses, a list of IP addresses, IP address mapping data, etc. as disclosed herein. As indicated by, the SMFmay communicate an event exposure notification to the NEF. The event exposure notification may include an indication of the event and the UPF data (e.g., unusual or suspicious accesses identified based on comparison to a machine-recognition of access patterns, applications/AFs the particular UEs accessed in the PDU session, particular websites accessed, applications used, IP address mapping information, etc.), a threshold, a maximum number of IP addresses, and/or the like. In some cases, the notification may further include an indication of the PDU session release/deactivation. As indicated by, the NEFmay communicate with the TAGto indicate the event exposure notification. In some embodiments, the NEFmay relay the event notification; in other embodiments, the NEFmay communicate portions of the event notification to the TAG.

250 250 250 Having obtained the UPF data, the TAGmay take various actions disclosed herein. For example, the TAGmay determine, from IP address mapping information received with the UPF data, that suspicious or unusual activity has occurred with respect to particular UEs. Accordingly, the TAGmay determine policies to enforce with respect to the particular UEs and may enforce those policies/service plans with respect to the UEs by communicating with the NEF based at least in part on the IP mapping information that identifies the external and/or internal cellular network IP addresses for the UEs that are to be the subject of the enforcement operations.

6 FIG. 600 600 500 500 600 600 600 illustrates an operation flow diagram corresponding to an embodiment of a methodfor exposing and using data from the UPF via the SMF with other event IDs. The methodmay generally align with method, with features disclosed herein with respect to methodbeing likewise applicable to method. However, the methodmay allow for operational flow depending on event type and may allow for use of new event IDs. For example, the methodmay be tailored to events corresponding to user traffic characteristics and/or uplink data characteristics, NAT mapping information, UE private IP addresses with or without mapping information, and/or the like.

605 250 218 As indicated by, the TAGmay communicate a request for access to UPF data to the NEF. The request may, for example, include an event ID indicating one or more requests for user traffic characteristics, uplink data characteristics, NAT mapping information, one or more UE private IP addresses with or without mapping information, and/or the like, as disclosed herein. The request may include specifications of a filter, for example, for the user traffic characteristics of interest. The specifications of the filter may be included in the parameters of the request.

610 218 212 218 As indicated by, the NEFmay communicate a message corresponding to the request to the UDM, which message may be responsive to the NEFapproving the request. In some embodiments, the message may be identical to the request. The message may include the event ID and the parameters of the request, which may include specifications of the detection criteria (e.g., of the filter).

615 212 214 620 214 220 621 622 623 214 212 218 250 As indicated by, the UDMmay communicate a corresponding message to the SMF. As indicated by, the SMFmay communicate with the UPFto provision the event parameters (e.g., specifying abnormal IP address detection) and obtain requested UPF data. As indicated by,, and, responses may be communicated. For example, some requested UPF data may be relayed. This may include data on the user traffic, for example. The SMFmay relay the responses to the UDM, which may in turn relay the responses to the NEF, which may in turn relay the responses to the TAG.

500 625 630 214 635 214 220 640 220 214 220 The remainder of the operational flow may be similar to that of method. As indicated by, DPI may be performed for select IP, such as unusual IP and, based on the filter, on all IP addresses corresponding to the parameters and/or IP addresses related to unusual/abnormal IP addresses. As indicated by, the SMFmay decide when and whether the PDU session should be released or deactivated. As indicated by, the SMFmay communicate with the UPFto coordinate a release. As indicated by, the UPFmay respond to the SMFwith the requested UPF data. For example, the requested UPF data retrieved and provided by the UPFmay include IP mapping information, one or more UE private IP addresses with or without mapping information, and/or other UPF data corresponding to the one or more UE public IP addresses provided with the event disclosure request.

645 214 218 650 218 250 250 As indicated by, the SMFmay communicate an event exposure notification to the NEF. As indicated by, the NEFmay communicate with the TAGto indicate the event exposure notification. Having obtained the UPF data, the TAGmay take various actions disclosed herein, such as determining policies to enforce with respect to the particular UEs and causing enforcement of those policies/service plans with respect to the UEs by communicating with the NEF based at least in part on the IP mapping information that identifies the external/public and/or internal/private cellular network IP addresses for the UEs that are to be the subject of the enforcement operations.

7 FIG. 700 700 700 illustrates an operation flow diagram corresponding to a methodfor UPF event exposure directly from the UPF, which may or may not be via the NEF in various embodiments. Providing access to, and exposure of, NEF events and UPF data directly from the UPF or via the NEF may advantageously provide the UPF data more quickly than some other methods. The methodmay be similar to the above-described methods in some respects, with features disclosed herein with respect to the above-described methods being likewise applicable to method. However, the UPF data may be provided directly from the UPF (which may be via the NEF in some embodiments) to the TAG or another AF without utilizing other NFs, which could otherwise cause delays. In some deployments, two or more of the UPF, the NEF, and the TAG may be on edges of the system (e.g., in the same geographical area) and, therefore, the UPF data may be more quickly provided directly from the UPF (via the NEF in some embodiments), as opposed to, for example, being provided via the SMF when it is a central node.

705 730 214 730 250 730 As indicated by, the NFmay communicate with the SMF, and PDU session information may be queried. In various embodiments, the NFmay correspond to one or a combination of the TAG, NWDAF, and/or other NFs. The NFmay receive information corresponding to the queried PDU session information.

710 730 220 730 730 As indicated by, the NFmay communicate directly with the UPFto request access to UPF data. As disclosed herein, the NFmay specify one or more events with one or more event IDs for which the NFrequests access to corresponding UPF data. For example, the request may include a request for IP mapping information, a request for one or more UE private IP addresses with or without mapping information, and/or a request for DPI. As disclosed herein, a number of different types of events and parameters may be requested. Such events or parameters may include area of interest parameters, time period, additional filters (e.g., maximum number of IP addresses, all or abnormal behavior, thresholds for abnormal behavior, and/or the like), reporting filters and corresponding parameters (e.g., one-time reporting, periodic reporting, event-trigger reporting, and/or other timing parameters), and/or the like, as disclosed herein.

220 715 220 720 220 In some embodiments, the UPFmay retrieve and provide IP mapping information, one or more UE private IP addresses with or without mapping information, and/or other UPF data corresponding to the one or more UE public IP addresses provided with the event disclosure request. In some embodiments, as indicated by, the UPFmay perform DPI for select IP addresses. As disclosed herein, the DPI may be performed based on the specified filter for unusual IP addresses (e.g., comparison to a user-specified or machine-learned/developed list of approved/verified/known addresses, hosts, and/or network IDs and/or of prohibited/flagged/suspicious addresses, hosts, and/or network IDs) or based on all IP addresses corresponding to the parameters and/or IP addresses related to unusual/abnormal IP addresses. As indicated by, the UPFmay detect events satisfying the detection criteria according to the specified event detection requested.

725 220 730 220 730 730 218 214 7 FIG. As indicated by, the UPFmay respond to the NFwith the UPF data, communicating one or more event exposure notifications. Though not shown in, in some embodiments, the UPFmay communicate the UPF data to the NEF, and the NEF may respond to the NFwith the UPF data. As disclosed herein, the event exposure notifications may include one or more UE private IP addresses, a list of IP addresses, IP mapping data, DPI results, and/or other UPF data. Having obtained the UPF data, the NFmay take various actions disclosed herein, such as determining policies to enforce with respect to the particular UEs and causing enforcement of those policies/service plans with respect to the UEs by communicating to the NEFand/or the SMF.

8 FIG. 800 800 800 805 730 218 730 730 218 illustrates an operation flow diagram corresponding to a methodfor NEF event exposure directly from the UPF, which may or may not be via the NEF in various embodiments. The methodmay be similar to the above-described methods in some respects, with features disclosed herein with respect to the above-described methods being likewise applicable to method. However, as indicated by, the NFmay communicate directly with the NEFwith a request for access to UPF data. The NFmay send an event exposure request, which may conform to other event exposure requests disclosed herein. For example, the event exposure request may correspond to one or more requests for one or more UE private IP addresses, NAT mapping information, DPI information, and/or the like. Accordingly, in some embodiments, the NFmay invoke a service to retrieve one or more UE private IP addresses. The event exposure request may include the one or more UE public IP addresses. The event exposure request may further include one or more port numbers corresponding to the one or more UE public IP addresses. The event exposure request may further include one or more N4 session identities, one or more Domain Network Name (DNN) specifications, one or more Single Network Slice Selection Assistance Information (S-NSSAI) specifications, area of interest parameters, and/or the like specified for the event exposure to allow the NEFor another component of the core to identify the domain to which the UPF service or SMF service belongs. The event exposure request may further include one or more of the optional requests disclosed herein, such as time period, additional filters, reporting filters and corresponding parameters, and/or the like.

730 730 730 The NFmay correspond to an AF in some embodiments. The NFmay not be a core NF but may be any NF residing outside core. The NFmay obtain one or more UE public IP addresses that it uses for the request(s) at least part in by detecting one or more UE public IP addresses in one or more packets outside of the core network, determining one or more source IP addresses (UE public IP addresses) of one or more devices of particular interest, receiving one or more UE public IP addresses from one or more systems that are remote from the core, and/or the like.

810 218 815 218 212 214 218 218 As indicated by, the NEFmay determine whether UPF service exposure or SMF service exposure is appropriate and approved for the request. As indicated by, the NEFmay communicate with the UDMand/or SMF, the PDU session information may be queried, and the NEFmay receive information corresponding to the queried PDU session information. The event exposure request may include one or more N4 session identities, one or more Domain Network Name (DNN) specifications, one or more Single Network Slice Selection Assistance Information (S-NSSAI) specifications, area of interest parameters, and/or the like to allow the NEFor another component of the core to identify the domain to which the UPF service or SMF service belongs. The DNN and S-NSSAI specifications can be used as additional identifiers. The DNN may indicate the domain to which the service belongs, whether there is an Internet data network, an IMS voice service, VPN, or another data network and domain to which the corresponding UE session belongs. The S-NSSAI may correspond to single network slice selection assistance information and may, for example, indicate a slice name (e.g., eMBB, URLLC, and/or V2X for a vertical slice or a public slice). For example, the external IP (public IP address) usually will be unique inside a Public Land Mobile Network (PLMN) but still can be reused in a different UPF.

730 220 220 218 220 218 220 Thus, for example, if the NFprovides the DNN and/or the S-NSSAI, such information may be used to select the right UPFby providing it to the Network Repository Function (NRF) in order to identify the right UPFif multiple UPFs can allocate the same external IP ranges. Accordingly, the NEFmay use the one or more N4 session identities, one or more DNN specifications, one or more S-NSSAI specifications, one or more area of interest parameters, and/or the like to search for and determine (e.g., via the NRF) the UPFthat can expose the requested data. Although only one UPF may be depicted in the figures for the sake of simplicity, there may be multiple and, indeed, many UPFs in the network, and, thus, the NEFmay identify the one UPFthat can expose the requested data.

820 218 220 218 220 218 218 220 825 830 220 835 220 218 As indicated by, the NEFmay communicate with the UPF, the communication corresponding to the event exposure request. In some embodiments, the NEFmay request from the UPFIP mapping information, one or more UE private IP addresses with or without mapping information, and/or other UPF data corresponding to the one or more UE public IP addresses provided with the event disclosure request. Like the event disclosure request, the request from the NEFmay include the one or more UE public IP addresses and the one or more corresponding port numbers. The request from the NEFmay further include one or more N4 session identities, one or more IP domain specifications, one or more DNN specifications, one or more S-NSSAI specifications, area of interest parameters, and/or the like specified for the event exposure. In response, the UPFmay retrieve and provide IP mapping information, one or more UE private IP addresses with or without mapping information, and/or other UPF data corresponding to the one or more UE public IP addresses. In some embodiments, as indicated byand, the UPFmay perform DPI for select IP addresses and may detect events satisfying the detection criteria according to the specified event detection requested, all as disclosed herein. As indicated by, the UPFmay communicate UPF data to the NEF, communicating one or more event exposure notifications, a list of IP addresses, IP mapping data, DPI results, and/or other UPF data.

220 730 805 840 218 730 730 218 214 In some embodiments, the UPF data may include the one or more UE private IP addresses retrieved by the UPFthat correspond to the one or more UE public IP addresses that were provided by the NFat. The UPF data may further include the one or more IP domains of the one or more UE private IP addresses. A UE private IP address may include the corresponding IP domain identifier, or the corresponding IP domain identifier may be provided along with the UE private IP address. In some embodiments, the UPF data may additionally include IP mapping data corresponding to the mapping of the UE public IP address to the UE private IP address. As indicated by, the NEFmay then respond to the NFwith the UPF data. Having obtained the UPF data, the NFmay take various actions disclosed herein, such as determining policies to enforce with respect to the particular UEs and causing enforcement of those policies/service plans with respect to the UEs by communicating to the NEFand/or the SMF.

It should be noted that the methods, systems, and devices discussed above are intended merely to be examples. It must be stressed that various embodiments may omit, substitute, or add various procedures or components as appropriate. For instance, it should be appreciated that, in alternative embodiments, the methods may be performed in an order different from that described, and that various steps may be added, omitted, or combined. Also, features described with respect to certain embodiments may be combined in various other embodiments. Different aspects and elements of the embodiments may be combined in a similar manner. Also, it should be emphasized that technology evolves and, thus, many of the elements are examples and should not be interpreted to limit the scope of the invention.

Specific details are given in the description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, well-known, processes, structures, and techniques have been shown without unnecessary detail in order to avoid obscuring the embodiments. This description provides example embodiments only and is not intended to limit the scope, applicability, or configuration of the invention. Rather, the preceding description of the embodiments will provide those skilled in the art with an enabling description for implementing embodiments of the invention. Various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the invention.

Also, it is noted that the embodiments may be described as a process which is depicted as a flow diagram or block diagram. Although each may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be rearranged. A process may have additional steps not included in the figure.

Having described several embodiments, it will be recognized by those of skill in the art that various modifications, alternative constructions, and equivalents may be used without departing from the spirit of the invention. For example, the above elements may merely be a component of a larger system, wherein other rules may take precedence over or otherwise modify the application of the invention. Also, a number of steps may be undertaken before, during, or after the above elements are considered. Accordingly, the above description should not be taken as limiting the scope of the invention.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

February 24, 2026

Publication Date

July 2, 2026

Inventors

Jinsook Ryu
Kazi Bashir
Mehdi Alasti
Siddhartha Chenumolu

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “USER PLANE FUNCTION EVENT EXPOSURE” (US-20260189892-A1). https://patentable.app/patents/US-20260189892-A1

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.